diff --git a/backend/src/ee/services/secret-rotation-v2/azure-client-secret/azure-client-secret-rotation-fns.ts b/backend/src/ee/services/secret-rotation-v2/azure-client-secret/azure-client-secret-rotation-fns.ts index bf134ecf3..32e2a5459 100644 --- a/backend/src/ee/services/secret-rotation-v2/azure-client-secret/azure-client-secret-rotation-fns.ts +++ b/backend/src/ee/services/secret-rotation-v2/azure-client-secret/azure-client-secret-rotation-fns.ts @@ -1,3 +1,4 @@ +/* eslint-disable no-await-in-loop */ import { AxiosError } from "axios"; import { @@ -18,6 +19,11 @@ import { getAzureConnectionAccessToken } from "@app/services/app-connection/azur const GRAPH_API_BASE = "https://graph.microsoft.com/v1.0"; +const sleep = async () => + new Promise((resolve) => { + setTimeout(resolve, 1000); + }); + export const azureClientSecretRotationFactory: TRotationFactory< TAzureClientSecretRotationWithConnection, TAzureClientSecretRotationGeneratedCredentials @@ -41,13 +47,16 @@ export const azureClientSecretRotationFactory: TRotationFactory< "0" )}-${now.getFullYear()}`; + const endDateTime = new Date(); + endDateTime.setFullYear(now.getFullYear() + 5); + try { const { data } = await request.post( endpoint, { passwordCredential: { displayName: `Infisical Rotated Secret (${formattedDate})`, - endDateTime: "2299-12-31T23:59:59Z" // effectively no expiration + endDateTime: endDateTime.toISOString() } }, { @@ -130,7 +139,10 @@ export const azureClientSecretRotationFactory: TRotationFactory< ) => { if (!credentials?.length) return callback(); - await Promise.all(credentials.map(({ keyId }) => revokeCredential(keyId))); + for (const { keyId } of credentials) { + await revokeCredential(keyId); + await sleep(); + } return callback(); };